Mitra OS

Privacy Policy

Version 2026-10-10. Effective 10 October 2026.

Contents

  1. Who we are
  2. What this policy covers
  3. The current state of our services
  4. Information you give us
  5. Information created through MITRA services
  6. Information we collect automatically
  7. Cookies and similar technologies
  8. How we use information
  9. AI and automated processing
  10. How we share information
  11. Service providers and subprocessors
  12. Sale, sharing, and targeted advertising
  13. Retention
  14. Deletion
  15. Security
  16. Your privacy rights
  17. Exercising your rights, and how we verify them
  18. California residents
  19. Other US states
  20. Users outside the United States
  21. Children
  22. Business transfers
  23. Third-party sites and services
  24. Legal and regulatory disclosures
  25. Aggregated and de-identified information
  26. No regulated professional advice
  27. Changes to this policy
  28. Contact us

1. Who we are

Mitra OS, Inc. ("Mitra OS," "we," "us," "our") is a Delaware corporation. Mitra OS operates this website and the MITRA services described in section 2. Where this policy says MITRA, it means the MITRA platform. Mitra OS is the controller (or, under US state privacy laws, the business) for the personal information covered by this policy.

Our registered office is c/o Legalinc Corporate Services Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, United States. That address is for written notices, which reach us through our registered agent. The fastest way to reach us about anything in this document is email: privacy@mitraos.ai.

2. What this policy covers

This policy applies to:

It does not cover services operated by someone else, including any MITRA service that another company operates under its own privacy policy. That company's policy, not this one, governs such a service unless and until we tell you within the service that Mitra OS has taken it over. From the point we tell you, this policy applies to that service.

Some relationships carry additional terms. Where an organization provides a service to you through Mitra OS under a contract, that contract (including any data processing agreement) governs the information it covers, and this policy applies only to the extent it does not conflict. The terms of service govern use of the services themselves.

3. The current state of our services

We describe this because a privacy policy that describes a platform you cannot yet use would be misleading about what is actually happening to your information today.

Today, the only practices operating under this policy are those of this website and its email addresses: our server logs (section 6) and the handling of email you send us (sections 4 and 11). This website has no forms, no accounts, no sign-in, and no analytics. The MITRA member platform, including its messaging, calendar, profile, and AI features, is in development and is not generally available from Mitra OS. Sections of this policy that describe the member platform tell you how it is intended to handle information, and they take practical effect for you when you get access to that functionality from Mitra OS.

We build and release changes to our services every week. Features are added, changed, and removed as we learn and as requirements change, so what this policy describes as available or planned can change quickly. When a change affects what personal information we collect or how we use it, we update this policy under section 27 before the change applies to you.

Throughout this policy we try to be explicit about the difference between what we do now, what we may do when a feature becomes available to you, and what would require a separate notice or your consent first.

4. Information you give us

Today, the information you give us is whatever you put in an email to help@mitraos.ai or privacy@mitraos.ai: your email address, your name if it appears in your address or message, the content of your message and any attachments, and anything else you choose to include. We use it to read and answer you.

When MITRA services become available from Mitra OS, depending on which you use, the information you give us may also include contact and identity details (such as a name, and a telephone number you verify with a one-time code), account and profile information (such as preferred name, username, date of birth, country, language and currency preferences, a short biography, and a profile photo), professional information where a form asks for it, records of which versions of our terms and this policy you accepted, and the content you submit to the services. Most profile fields will be optional. If we ever ask for identity verification documents, or you give us information that is sensitive under the law where you live, we will use it only as reasonably necessary to provide and secure the service, except with your consent or as the law requires.

5. Information created through MITRA services

When a MITRA member service is available to you from Mitra OS, using it will generate information, including messages and conversations (including conversations with AI agents), the prompts and context you give AI features and the outputs they return, requests you make and the record of how they were handled, calendar and scheduling information where you use those features, preferences and settings, and audit records of consequential actions.

Features not currently offered. We do not currently offer, under this policy, general document or file upload, payment or subscription processing, health or wearable data collection, biometric identification performed by us, location tracking, or push notifications. Some are designed for and planned in the product. If and when we enable one, we will update this policy and, where the law requires it, give you notice or obtain your consent before that processing begins.

Biometrics. Where you unlock a MITRA mobile application with Face ID, Touch ID, or an Android biometric, that check is performed by your device against data held in your device's own secure hardware. Your fingerprint or face data is not transmitted to us and we do not receive or store it. What we receive is the result: that your device confirmed it was you.

Device records. When you register a device to sign in without a password, the application sends us an identifier it generates for that device, along with the public key for the credential. We keep both for as long as that sign-in method is registered, so that we can tell your devices apart, show you which ones have access, and let you remove one. This identifier is not an advertising identifier, we do not use it to track you across other apps or websites, and it is not shared for advertising.

6. Information we collect automatically

Server and delivery logs. Our content delivery network records requests to this website, including IP address, timestamp, the resource requested, referring page, and user-agent string. We use these to operate, troubleshoot, and secure the website, and to detect abuse. They are deleted automatically 90 days after they are written.

This website does not use analytics, advertising, or cross-site tracking technologies, and it loads no third-party resources: the stylesheet and all other assets are served from our own infrastructure, so loading a page does not send a request to another company. We consider the logging described above to be technical and security processing rather than tracking, but we disclose it here rather than describe the website as collecting nothing.

When MITRA services are available from Mitra OS, they will also record application events such as sign-in attempts, errors, and security-relevant activity, together with session and device information needed to keep you signed in and to protect accounts. We will describe the retention periods for those records here before they apply to you.

7. Cookies and similar technologies

This website sets no cookies and uses no local storage, session storage, or similar on-device technologies. It runs no scripts. Light and dark appearance follows your device's setting without our storing anything. If that changes, we will say so here first.

8. How we use information

We use personal information to:

We do not use your information to advertise to you, and we do not run any advertising or marketing analytics program. We do not send marketing email, calls, or texts. If that ever changes we will ask for your separate consent first.

Legal bases. Where the law that applies to you requires a legal basis for processing, we generally rely on: performance of a contract with you, or steps taken at your request before entering one; our legitimate interests in operating, securing, and improving our services and in preventing fraud and abuse, where those interests are not overridden by your rights; your consent, where we ask for it; and compliance with legal obligations. Where we rely on consent, you may withdraw it at any time, which does not affect processing carried out before you withdrew it.

9. AI and automated processing

MITRA is designed as an AI platform, so we describe this separately. This website uses no AI features and processes none of your information with AI.

When MITRA AI features are available from Mitra OS, the input you provide, and context the platform assembles to answer you, will be submitted to a large language model. MITRA is built to work with more than one AI provider. When a feature is served by a third-party model, your input and the assembled context are transmitted to that provider, which processes them on our behalf as a service provider or subprocessor. That provider's own terms govern how it handles what it receives, including whether it retains inputs and outputs and for how long. Before we enable a third-party AI provider for member content, we will identify it here and describe the applicable retention and training controls.

Training. Mitra OS does not build or train its own AI models, and we do not use your content to do so. We do not provide member content to any third party for the purpose of training that third party's models. We cannot make an unconditional promise about every provider's practices for all time: what a provider may do with data it receives is set by our contract with that provider, and where a provider's standard terms would permit training on inputs, we will either configure the service to prevent it, contract for its exclusion, or disclose it here before that provider processes member content.

AI outputs are not guaranteed. AI systems produce text by prediction. Outputs may be inaccurate, incomplete, outdated, biased, or otherwise unexpected, and they may be confidently wrong. You are responsible for reviewing AI-generated output before relying on it. AI output is not professional advice of any kind (see section 26).

Automated decisions. We do not use AI or other automated processing to make decisions that produce legal effects concerning you or similarly significantly affect you without human involvement. MITRA is designed so that consequential actions, meaning those touching money, health information, or an irreversible booking, require your explicit confirmation before they are carried out. If we introduce automated decision-making of the kind that triggers additional rights under the law that applies to you, we will describe it here and honor those rights.

10. How we share information

We do not disclose your information except as described in this policy. Specifically, we may disclose it:

Where we disclose information because the law compels it, we will tell you unless we are prohibited from doing so or unless doing so would be unreasonable in the circumstances, for example where there is a risk to someone's safety.

11. Service providers and subprocessors

Like most software companies, we rely on third parties to run our services. We use many, and they change, so we describe them by category rather than by name. They act on our instructions, are bound by contract or by their standard terms, and receive only the information reasonably necessary for the function they perform. Today the categories are:

When MITRA member services become available from Mitra OS, we expect to use providers in these further categories: databases and backup; identity, authentication, and one-time-code delivery, including SMS; sign-in and device platform providers, such as those behind "Sign in with" options and mobile app stores; AI, large language model, and search providers (see section 9); email delivery for operational and security notices; logging, monitoring, and security tooling; payment processing, if and when we charge for a service; customer support tooling; and professional services such as legal, accounting, and audit. We do not publish a list of individual providers in this policy. You can ask for the providers that process your information by writing to privacy@mitraos.ai, and we will tell you the categories and, where the law requires it, the names that apply to you.

12. Sale, sharing, and targeted advertising

These words have specific meanings under US state privacy laws, so we use them carefully rather than saying simply that we do not share data, which would be inaccurate given that vendors process information for us.

If this ever changes, we will update this policy and provide any opt-out mechanism the law requires before the change takes effect.

13. Retention

We keep personal information for as long as reasonably necessary for the purposes described in this policy, and then delete it or de-identify it. In deciding how long, we consider how long we need it to provide the service, whether we need it to resolve a dispute or enforce our agreements, whether a law or a tax, accounting, or audit obligation requires us to keep it, and the risks of keeping it against the risks of losing it.

Specific periods we can state today:

Information may persist in encrypted backups and disaster-recovery copies after it is removed from our live systems, and is deleted or overwritten as those copies age out on their normal cycle. Information subject to a legal hold is retained until the hold is lifted.

14. Deletion

You can ask us to delete personal information we hold about you by writing to privacy@mitraos.ai. We will verify your request as described in section 17 and act on it within the time the applicable law allows.

We will delete or de-identify what we can, but deletion is not unlimited and we will not promise you that it is. We may retain information where it is reasonably necessary to:

Content in another person's copy of a shared conversation, and content already delivered to a provider at your direction, may not be within our power to remove. Where we cannot delete something, we will tell you why, and we will restrict its use to the purpose that justifies keeping it.

15. Security

We maintain administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, use, disclosure, alteration, and destruction, taking into account the nature of the information and the risks involved. For this website and its email handling, these currently include: encryption of traffic in transit using TLS; encryption of stored data at rest by our cloud provider; private storage with no public access; email authentication records (SPF, DKIM, and DMARC) on our domain to limit spoofing; and scanning of inbound mail for spam and viruses before it is forwarded.

We have tried to keep this section to what is in place, and we do not represent that a control that is planned is already protecting your information. Mitra OS has not obtained a SOC 2 report, ISO 27001 certification, or any comparable third-party security certification or attestation, and we do not claim compliance with any such framework.

No method of transmitting or storing information can be guaranteed to be completely secure, and we cannot and do not guarantee the security of information you transmit to us or that we hold. Email in particular may cross networks we do not control. Where the law requires us to notify you or a regulator of a security breach involving your personal information, we will do so as that law requires.

Your part. Keep your device, your credentials, and your account secure, and tell us promptly at privacy@mitraos.ai if you believe someone has gained unauthorized access to your account. Nothing here shifts to you an obligation that the law places on us.

16. Your privacy rights

Depending on where you live and which law applies, you may have the right to:

Which of these you actually have is set by the law that applies to you, and some of these laws apply to a company only above certain thresholds. We do not assert that every law is applicable to Mitra OS. As a matter of policy, we accept and act on access, correction, and deletion requests from anyone who contacts us, whichever law does or does not apply, subject to the verification step in section 17 and the limits in section 14.

17. Exercising your rights, and how we verify them

Write to privacy@mitraos.ai and tell us what you are asking for.

Verification. Before we act on a request, we take reasonable steps to confirm that it comes from you or from someone you have authorized. What we ask for depends on the sensitivity of the request: confirming control of the email address or phone number associated with the record is typical, and a request to access or delete more sensitive information may need more. We will not disclose personal information to a requester we cannot reasonably verify, and we may decline a request on that basis. Information we collect to verify a request is used only for that purpose and for our record of having handled it.

Authorized agents. Where the applicable law permits, an authorized agent may submit a request for you. We may ask the agent for proof of authorization, and we may ask you to verify your own identity with us directly or to confirm that you gave the agent permission.

Timing and outcome. We respond within the period the applicable law sets, and we will tell you if we need an extension the law allows. If we decline a request in whole or in part, we will tell you why, and we will tell you how to appeal where the applicable law provides an appeal. There is no charge for a reasonable request; we may charge a reasonable fee, or decline, where a request is manifestly unfounded, excessive, or repetitive, to the extent the law permits.

You will not be denied service, charged a different price, or given a different level of quality because you exercised a privacy right.

18. California residents

This section applies to California residents where the California Consumer Privacy Act, as amended by the California Privacy Rights Act, applies to our processing of your information. We provide the following disclosures without conceding that any particular threshold for applicability is met.

The categories of personal information we may collect are described in sections 4 through 6. In the terms the statute uses, these correspond to identifiers; personal information listed in the California customer records statute; commercial information; internet or other electronic network activity information; professional or employment-related information, where you provide it; and inferences drawn from the foregoing. To the extent information such as the contents of your messages is treated as sensitive personal information, we use and disclose it only for purposes the statute permits without an option to limit, meaning to provide the service you requested, to secure it, and for the other permitted business purposes described in this policy. Sources, purposes, and disclosure practices are described in sections 4 through 12. Retention is described in section 13.

We have not sold personal information or shared it for cross-context behavioral advertising, and we have no actual knowledge of selling or sharing the personal information of consumers under 16 years of age. California residents may exercise the rights to know, access, correct, delete, and limit as described in sections 16 and 17, including through an authorized agent, without discrimination.

19. Other US states

Residents of other states with comprehensive consumer privacy laws, including Colorado, Connecticut, Delaware, Virginia, Utah, Texas, Oregon, Montana, and others as those laws come into force, have rights of the kind described in section 16 where the applicable law applies to us. This includes, in most of those states, a right to appeal a refusal of a request, and a right to contact the state attorney general if the appeal is unsuccessful. Submit requests and appeals to privacy@mitraos.ai.

Because we do not sell personal information, do not process it for targeted advertising, and do not engage in profiling that produces legal or similarly significant effects, the opt-out rights those laws provide do not currently have anything to operate on. We do not recognize a universal opt-out preference signal today, because there is no processing for it to control; if that changes, we will honor those signals where the law requires and will say so here.

20. Users outside the United States

Mitra OS is a United States company and our infrastructure is located in the United States. Our services are directed to users in the United States. If you access them from elsewhere, you do so on your own initiative, and the information you provide is transferred to and processed in the United States, where privacy laws differ from those in your country and where government authorities may be able to access information under United States law.

We are not claiming compliance with the General Data Protection Regulation, the UK GDPR, the Swiss Federal Act on Data Protection, Canada's PIPEDA, Brazil's LGPD, India's Digital Personal Data Protection Act, or any other non-US framework. We have not appointed an EU or UK representative or a data protection officer, and we have not put in place a standalone international data transfer mechanism of our own; for transfers carried out by our infrastructure providers we rely on the terms those providers make generally available in their data processing agreements. Before we offer the services into a market where one of those frameworks applies to us, we will put the required arrangements in place and describe them here.

In the meantime, if you are outside the United States you may have rights under the law where you live. Write to privacy@mitraos.ai. We handle requests from outside the United States the same way we handle requests from inside it, and we will tell you honestly where we cannot offer something that a local framework would otherwise require.

21. Children

This website and MITRA are intended for adults. They are not directed to children, and we do not knowingly collect personal information from anyone under 18. If you believe a child has provided us with personal information, write to privacy@mitraos.ai and we will delete it.

MITRA is designed to include family features, and some of those could involve information about minors. We will not enable any feature that collects personal information from or about a minor until it has had a separate privacy and legal review, and until this policy has been updated to describe it and, where required, verified parental consent has been obtained.

22. Business transfers

If Mitra OS is involved in a merger, acquisition, financing, due diligence, reorganization, restructuring, sale of all or part of its assets or business, bankruptcy, receivership, or other change of control, personal information may be reviewed by, and transferred to, the parties to that transaction and their advisers, subject to confidentiality protections appropriate to the stage of the transaction. If personal information is transferred and becomes subject to a different privacy policy, we will notify you as the applicable law requires.

If a MITRA service moves to Mitra OS from another operator, as section 2 describes, we will tell you within that service before this policy applies to it.

23. Third-party sites and services

Our website and applications may link to, or let you connect to, services operated by other companies. Those services are controlled by them, not by us. Their handling of your information is governed by their own privacy policies, and we are not responsible for their practices. Review the privacy policy of any service before you use it or connect it, and manage what you have connected through that service's own controls as well as ours.

24. Legal and regulatory disclosures

We may access, preserve, and disclose information where we reasonably believe it is necessary to:

We review demands for information and, where we consider a demand improper or overbroad, we may challenge it. Where we are permitted to notify you of a demand for your information, our practice is to do so.

25. Aggregated and de-identified information

We may create aggregated, statistical, or de-identified information from the information we hold, and use and disclose it for any lawful purpose, including operating, analyzing, and improving our services and describing them publicly. Where we hold information in de-identified form, we maintain it in that form, do not attempt to re-identify it except to test the effectiveness of our de-identification or as the law otherwise permits, and require the same of recipients by contract.

We describe such information as de-identified or aggregated rather than anonymous, because de-identification is a matter of degree and we do not claim that re-identification is impossible.

26. No regulated professional advice

Mitra OS is a software company. It is not a registered investment adviser, a broker-dealer, a bank, an insurance producer, a law firm, a tax adviser, or a healthcare provider, and it is not acting in any of those capacities when you use our services. Nothing produced by MITRA, including AI-generated output, is financial, investment, tax, legal, insurance, medical, or other regulated professional advice, and none of it should be relied on as a substitute for a licensed professional. Where a service is delivered by a licensed provider through the platform, that provider is responsible for the regulated advice it gives, under its own terms and its own regulator. The fact that we may process financial, health-adjacent, or other regulated categories of information does not make Mitra OS a regulated financial, health, or professional services firm, and does not create a fiduciary, advisory, or professional relationship between us.

27. Changes to this policy

We may update this policy as our services, our providers, and the law change. Because we release changes to our services every week, this policy may be updated often. Every version carries a version identifier and, once in force, an effective date, both shown at the top of this page.

Changes generally apply going forward from the date the updated version takes effect. If we make a material change, we will take steps reasonably designed to bring it to your attention before it applies to you, such as a notice in the service or on this website. Where the law requires your consent to a particular change, we will obtain it. Where it does not, continued use of the services after an update takes effect means the updated policy applies to that use, to the extent the law permits.

28. Contact us

For any privacy question, or to exercise a right described in this policy, write to privacy@mitraos.ai. This is the address to use, and we monitor it.

Mitra OS, Inc., a Delaware corporation.

Registered office: c/o Legalinc Corporate Services Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, United States.

If you are in a jurisdiction with a data protection authority and you are not satisfied with our response, you may be entitled to complain to that authority.